Privacy Policy

MDG YouTube Autopost · Last updated 24 August 2026

MDG YouTube Autopost ("the app") is a scheduling tool that uploads a creator's own video files to their own YouTube channel at a time they choose. This policy explains exactly what Google user data the app accesses, how it is used, who it is shared with, how it is protected, and how long it is kept.

The app runs entirely on the user's own computer. It has no server, no hosted backend and no database outside the user's machine. No Google user data is transmitted to us, to any third party, or to any remote system at any time. The only network connections the app makes are directly from the user's computer to Google's own APIs.

1. What Google user data the app accesses

The app requests the following OAuth scopes, and no others:

ScopeWhat it accessesWhy it is needed
https://www.googleapis.com/auth/youtube.upload Permission to upload video files to the authenticated user's own YouTube channel, including the title, description and tags supplied by the user for those uploads. This is the core function of the app. Without it the app cannot upload the user's video at the scheduled time. No narrower scope permits video upload.
https://www.googleapis.com/auth/youtube.readonly Read-only access to the identity of the authenticated user's channel — specifically the channel ID and channel title returned by channels.list?mine=true. Used as a safety check. Before every upload the app confirms the credentials resolve to the channel the user configured, and refuses to upload if they do not. This prevents a video being published to the wrong channel if the wrong account was selected during sign-in. No video content, watch history, analytics, subscriber data, comments or personal profile information is read.

The app does not request, access, or receive: Gmail data, Google Drive data, Google Contacts, Google Calendar, location data, YouTube analytics, YouTube comments, subscriber lists, or any other Google user data.

2. How the app uses Google user data

Google user data is used solely to perform the action the user has asked for, at the moment they have asked for it:

Google user data is not used for advertising, for profiling, for building any user or audience model, for resale, or for training artificial intelligence or machine learning models. It is not used for any purpose beyond those listed above.

3. With whom Google user data is shared, transferred or disclosed

Google user data is not shared, transferred, or disclosed to anyone.

Specifically, it is not disclosed to us as the developer, to any other user, to any third-party company, to any advertising network, to any analytics provider, to any data broker, or to any AI or machine learning service. There is no server to which the data could be sent.

Data flows only between the user's own computer and Google's own APIs over an encrypted connection. The only exception is where disclosure is required by law, in which case we could only disclose data we actually hold — which, in the case of Google user data, is none.

4. How Google user data is protected

Credentials and tokens

OAuth access tokens and refresh tokens are stored in the macOS Keychain, the operating system's encrypted credential store, protected by the user's own login password and by macOS file protections. Tokens are never written to configuration files, plain text files, logs, or any other location on disk. They are never printed to the screen and never transmitted anywhere except directly to Google's token endpoint over HTTPS.

Data in transit

All communication with Google is over HTTPS (TLS). The app uses Google's published API endpoints and resumable upload protocol.

Local interface

The app's optional local web interface binds only to 127.0.0.1 — the user's own machine — and is not reachable from any network. It executes only a fixed, hard-coded list of permitted commands, and never displays or logs credential values.

Sensitive data

The app treats OAuth tokens as its only sensitive data. It stores no passwords, no payment information, no government identifiers, no health or biometric data, and no personal information about any person other than the authenticated account holder.

Access control

Because everything runs locally, only a person with physical or authenticated access to the user's own computer and Keychain can reach the stored credentials.

5. Retention and deletion of Google user data

What is retained

The app retains only the OAuth access token and refresh token, in the macOS Keychain, and a local record of which video files were uploaded and when. The video files themselves belong to the user and are stored on their own computer. No Google user data is retained anywhere else.

How long it is retained

Tokens are retained only for as long as the user continues to use the app. Access tokens are short-lived and are replaced automatically when they expire. Refresh tokens are retained until the user disconnects the app or deletes them.

How the user deletes it

A user can remove all Google user data held by the app at any time, by either of these routes:

  1. Revoke access at Google. Visit myaccount.google.com/permissions, select this app, and choose "Remove access". This immediately invalidates the stored tokens.
  2. Delete the stored credentials. Open the macOS Keychain Access application, search for the entries beginning MDG_YOUTUBE_, and delete them. Deleting the app's folder removes the local upload records.

Because no Google user data is held anywhere other than the user's own computer, these actions delete it in full. There is no copy held by us or by any third party for us to delete.

6. Children

The app is not directed at children and is not intended for use by anyone under 18.

7. Changes to this policy

If this policy changes, the revised version will be published at this address with an updated date at the top.

8. Contact

Questions about this policy or about data handling can be sent to mattdoesgolfmail@gmail.com.